‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. romaniitedomum · · focus · HN ↗
    An interesting observation that I encountered somewhere, I forget where, is that AIs when writing code introduce vulnerabilities at a rate similar to humans writing the same code. So we're looking at a massively accelerated volume of security vulnerabilities for the foreseeable future thanks to AI-assisted security research, and we can expect no reduction in new vulnerabilities from the AIs writing the code.
    1. biwills · · focus · HN ↗
      Do we know the code behind these vulnerabilities were written by AI? It seems like if anything AI was used to find exisitng vulnerabilities that would otherwise be used/sold as zero days and go unreported.

      It was always the case that finding vulnerabilities in software was easier than writting perfect software. I'm hopeful that we can use AI to make software more secure over time. Project Zero [1] and others has shown many times the past few years (pre LLMs) that automated fuzzing and other forms of dynamic analysis are very effective, which bodes well for automated testing via LLMs!

      I agree that more code = more bugs overeall, but there are slow moving codebases that run some of the worlds most valuable software. Seems like using AI to find vulnerabilities in that code is a huge win across the board.

      [1]: <a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?q=site%3Aprojectzero.google&amp;q=fuzzing" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?q=site%3Aprojectzero.google&amp;q=...

      1. romaniitedomum · · focus · HN ↗
        &gt; Do we know the code behind these vulnerabilities were written by AI? It seems like if anything AI was used to find exisitng vulnerabilities that would otherwise be used&#x2F;sold as zero days and go unreported.

        I was speaking in the general sense, not of these vulnerabilities specifically. I am of the view that AIs for the foreseeable won&#x27;t produce code that is any better from a security point of view than something human written, so AIs will produce new vulnerabilities at least as fast as they find them and the rest of us will be faced with massive headaches like the one in the original post.

        &gt; It was always the case that finding vulnerabilities in software was easier than writting perfect software. I&#x27;m hopeful that we can use AI to make software more secure over time. Project Zero [1] and others has shown many times the past few years (pre LLMs) that automated fuzzing and other forms of dynamic analysis are very effective, which bodes well for automated testing via LLMs!

        And yet, we are not seeing a drop-off in new vulnerabilities being discovered. We keep assuming that the list of bugs is getting smaller and we&#x27;ll find them all eventually, but that is not the case for any software that I know of.

        &gt; I agree that more code = more bugs overeall, but there are slow moving codebases that run some of the worlds most valuable software. Seems like using AI to find vulnerabilities in that code is a huge win across the board.

        It might be, yet, as I said just above, we are not seeing a drop-off in new vulnerabilities being found. The trickle of vulnerabilities has become a flood across all open source software, and already breakages and problems are occurring as maintainers struggle to keep up. Administrators, likewise, are struggling to keep systems updated. Just a week or so ago a security patch to rsync on RHEL broke rsync so completely that it could no longer handle symbolic links.

        Critical CVEs used to be relatively infrequent, but they&#x27;re becoming a weekly or even daily occurrence. None of us are prepared for this eventuality.

        1. literalAardvark · · focus · HN ↗
          &gt;And yet, we are not seeing a drop-off in new vulnerabilities being discovered. We keep assuming that the list of bugs is getting smaller and we&#x27;ll find them all eventually, but that is not the case for any software that I know of.

          It&#x27;s worth factoring in that AI has gotten better rather quickly, so there&#x27;s no reason to expect it not to continue to find new bugs even if we&#x27;ve correctly fixed what Mythos found. The search depth is increasing.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.